Pentester and Vulnerability Mgt Engineer

2 weeks ago


Charlotte, North Carolina, United States Belk Full time

Security Engineer – Penetration Testing & Vulnerability Management

We are looking for a penetration tester/vulnerability engineer to join our team to help protect the organization from cyber threats. As a penetration tester, you will be responsible for conducting ethical hacking activities to identify and exploit vulnerabilities in systems, networks, applications, and devices. You will be involved in red teaming, purple teaming, and active threat-hunting exercises to simulate real-world attacks and test the effectiveness of our security controls and incident response capabilities. You will also be expected to lead and manage vulnerability and patch management programs to ensure timely remediation of security issues.

This role is fully remote with quarterly travel to Belk, Inc. headquarters and must be worked in the ET time zone. This role will report to the Manager, Cybersecurity Operations & Incident Response.

Essential Duties and Responsibilities

Vulnerability Management

  • Compiling and tracking vulnerabilities and mitigation results to quantify program effectiveness.
  • Creating and maintaining vulnerability management policies, procedures, and training
  • Analyzing cyber defense policies and configurations and evaluate compliance with regulations and organizational directives.
  • Maintain knowledge of applicable cyber defense policies, regulations, and compliance documents related to cyber defense assessment.
  • Prepare reports identifying technical and procedural findings and providing recommended remediation strategies/solutions.
  • Perform technical (evaluation of technology) and nontechnical (evaluation of people and operations) risk and vulnerability assessments of relevant technology focus areas (e.g., container registry scanning, open-source vulnerability scanning, network/host vulnerability scanning, cloud security posture management, and source code scanning.
  • Analyze CIS benchmarks compliance for multiple platforms, including on-premises and cloud resources, and generate reports to achieve compliance by meeting organizational security standards.
  • Maintain weekly reports for work-in-progress efforts across cybersecurity operations resources.
  • Manage the exception process for vulnerabilities, patching, or pen-testing findings that cannot meet Belk's Standards and/or the remediation SLA.

Penetration Testing

  • Perform formal penetration tests on web-based applications, networks, and computer systems to include Windows environments from initiation to closure.
  • Threat modeling
  • Carry out testing of the cloud environment to expose weaknesses in security.
  • Determine methods that attackers could use to exploit weaknesses and logic flaws.
  • Perform security reviews of application designs, source code, and deployments as required, covering all types of applications (web applications, web services, mobile applications, SaaS)
  • Perform physical security reviews.
  • Participate in Security Assessments and IT auditing of networks, systems, and applications.
  • Use, design, and create penetration tools and tests.
  • Document findings for management and technical staff and recommend mitigating actions.

Required Knowledge and Skills

  • Proficiency in using penetration testing tools like Metasploit, Burp Suite, Nmap, Wireshark, and vulnerability scanners.
  • Understanding of standard network protocols, operating systems (Windows, Linux, macOS), and web technologies.
  • Knowledge of common web application vulnerabilities like SQL injection, cross-site scripting (XSS), and cross-site request forgery (CSRF).
  • Familiarity with scripting languages like Python, Bash, or PowerShell to automate tasks and develop custom tools.
  • Solid understanding of cybersecurity principles, secure coding practices, cloud infrastructure, and network security controls.
  • Knowledge of common security frameworks and compliance standards, such as OWASP, PCI DSS, NIST, and MITRE ATT&CK Framework.
  • Strong analytical thinking and problem-solving abilities to identify vulnerabilities, analyze their impact, and recommend appropriate solutions.
  • Knowledge of system administration concepts, including server configuration, user, and patch management.
  • Excellent communication skills to communicate findings, vulnerabilities, and recommendations effectively to technical and non-technical stakeholders.
  • Willingness to continuously learn new tools, methodologies, and technologies in the rapidly evolving field of cybersecurity.
  • Understanding the retail business context to prioritize risks and align security assessments with organizational objectives is essential.
  • Ability to work effectively as a team, collaborate with other security professionals, and share knowledge and expertise.

General Requirements:

  • A bachelor's degree in computer science, Information Security, or a related field is desirable.
  • At least one of the following certifications: OSCP, GPEN, PNPT, PenTest+, or similar certification
  • 3+ years of overall IT experience.
  • 3+ years of experience in vulnerability management.
  • 3+ years of experience in ethical hacking.
  • 2+ years of experience in incident management.
  • 3+ years of experience in systems management and administration is desireable

#LI-REMOTE

#LI-CR1

#IND3



  • Charlotte, North Carolina, United States Bank of America Full time

    Job Description:At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. Responsible Growth is how we run our company and how we deliver for our clients, teammates, communities and shareholders every day.This job is responsible for assessing the bank's technologies, applications, and...

  • IT Procurement Lead

    3 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID C) DescriptionAs our company continues to expand its digital presence and leverage technology for business growth, we are seeking an experienced and knowledgeable IT Security and Compliance Manager to join our team. This critical role will be responsible for establishing and maintaining robust security measures, ensuring compliance with relevant...

  • Project Engineer

    3 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID DescriptionA Project Engineer is directly responsible for the technical excellence and the technical coordination of assigned projects and indirectly responsible for project profitability, with these responsibilities crossing multiple engineering disciplines. This individual will guide the engineering process in addition to monitoring all phases of...


  • Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID DescriptionAs B&W continues to expand our reach in the Energy field, we are looking to hire experienced Boiler/Power Industry Process Engineers. The ideal candidate will have process engineering experience in Coal, Oil and Gas, Biomass, or Waste to Energy technology. Must have familiarity with grate/stoker, burner, or fluid bed combustion, heat and...


  • Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID W)DescriptionB&W is seeking experienced Mechanical, Chemical, and Civil Engineering, or similar Engineering Technology degreed personnel, to join our team of talented Field Service Engineers, who provide best in the industry expertise and support on a broad range of B&W utility, industrial, and environmental products to our customers.As a Field...

  • IC&E Engineer

    4 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID DescriptionAn IC&E Engineer is responsible for instrumentation, controls, and electrical system design for boiler and environmental projects, including new build and retrofit contracts and proposals. As a discipline lead on projects, the individual must be able to work within a team to ensure success of a project. The individual will be frequently...

  • Technical Designer

    4 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID A)DescriptionThe Technical Designer functions as project leader in directing Technical Design work on a single contract or project. Working from information at the proposal, early contract or final design stages, this individual functions as the interface between various engineering departments and Project Management. This role falls within our Design...


  • Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID C) DescriptionAs a Code Data Assistant Manager, this position is responsible for production and engineering support across B&W as it pertaines to maintaining all documentation related to American Society of Mechanical Engineer's (ASME) code for Watertube Boilers and unfired pressure vessels. As a critical component within the organization, this...

  • Proposal Specialist

    3 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID Z) DescriptionWe are currently seeking an experienced Proposal Specialist within the Global Parts and Service organization to develop complete quote proposals, specifically for General Boiler Parts and Pressure Parts, within the Global Parts & Services organization. The Proposal Specialist reports to the Product Support Manager and may also support...

  • Planner Scheduler

    3 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID Y)DescriptionThe Planner Scheduler performs complex aspects of planning/scheduling, project controls, and administrative scheduling functions with minimal supervision. They are responsible for analyzing data to assist in the development of critical path networks (CPN) schedules on proposals and contracts. This position monitors progress and reports...

  • Logistics Coordinator

    4 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID L) DescriptionThe Logistics Coordinator 2 serves as a consultant to various operating units within the business, performing studies on complex logistics movements such as modularization, estimating, purchasing, and sales negotiations by identifying and advising engineering, purchasing, and marketing of transportation capabilities and limitations. This...


  • Charlotte, North Carolina, United States Johnson, Mirmiran, and Thompson Inc. Full time

    Johnson, Mirmiran & Thompson is a dynamic, 100% employee-owned consulting firm of more than 2,000 professionals that provides a full range of multi-disciplined engineering, architecture, information technology, and related services to public agencies and private clients throughout the United States. JMT, currently ranked #59 on Engineering News-Record's list...


  • Charlotte, North Carolina, United States Bank of America Full time

    Job Description:Position Summary The Application Delivery Service Network Product Manager role is responsible for maximizing the value for our Network Services product line that include load balancing, traffic management and application delivery controller technologies. Key responsibilities include defining the vision and roadmap for their products,...

  • Job Description

    4 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job Description Project Controls Specialist D)DescriptionThe Project Controls Specialist is responsible for implementing and carrying out the project controls function (cost and schedule) on various projects which includes project set-up and close-out, cost tracking, earned value management, change management, risk management, cost reporting, cost analysis &...

  • Architect II

    4 days ago


    Charlotte, North Carolina, United States Johnson, Mirmiran, and Thompson Inc. Full time

    Johnson, Mirmiran & Thompson is a dynamic, 100% employee-owned consulting firm of more than 2,000 professionals that provides a full range of multi-disciplined architecture, engineering, information technology, and related services for K-12 schools, higher education, and to public agencies and private clients throughout the United States. JMT is currently...

  • Purchasing Agent

    3 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID T)DescriptionSourcing and Purchasing of assigned commodities and services which may include Indirect MRO, Valves, Hardware, PV&F, Power Transmission, Gears, Outside Processing, and other items as assigned. Day to day operations, include gathering requirements, requesting proposals & quotes from potential suppliers, evaluating bids, developing and...

  • Senior Accountant

    3 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID P)DescriptionThe Senior Accountant will be involved in various ongoing monthly duties as well as other auxiliary accounting duties. Monthly duties include balance sheet and account analysis, preparing and reviewing journal entries and account reconciliations, all while adhering to strict timelines related to closing schedules. Auxiliary accounting...

  • Senior Accountant

    4 weeks ago


    Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID A)DescriptionThe Sr Accountant will be involved in various ongoing monthly duties as well as other axillary accounting duties. Monthly duties include balance sheet and account analysis, reviewing and approving journal entries and account reconciliations, all while adhering to strict timelines related to closing schedules.Axillary accounting duties...


  • Charlotte, North Carolina, United States Babcock and Wilcox Company Full time

    Job ID J)DescriptionThe Director of Project Managers will lead a team of project management professionals ensure projects are executed effectively and efficiently assuring on time delivery and within budgetThe ideal candidate will have the necessary leadership skills, business acumen and strategic knowledge to challenge the status quo and execute overall...


  • Charlotte, North Carolina, United States Windermere Executive Search and Recruitment Full time

    SENIOR MANAGER, MELT OPTIMIZATION Location: North Carolina, United StatesClient is seeking a Senior Manager, Melt Optimization in NC. This role plays a pivotal role in steering the strategic blend management and cost efficiency of titanium (Ti) and nickel (Ni) materials at our Specialty Materials business unit. This position is integral to the enhancement of...